vendor:
ServiceDesk
by:
Pedro Ribeiro
7,2
CVSS
HIGH
Authenticated Arbitrary File Upload
22
CWE
Product Name: ServiceDesk
Affected Version From: 6.5
Affected Version To: 7.1.0
Patch Exists: YES
Related CWE: CVE-2016-1593
CPE: Novell ServiceDesk
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2016
Novell ServiceDesk Authenticated File Upload
This module exploits an authenticated arbitrary file upload via directory traversal to execute code on the target. It has been tested on versions 6.5 and 7.1.0, in Windows and Linux installations of Novell ServiceDesk, as well as the Virtual Appliance provided by Novell.
Mitigation:
The user should ensure that the application is up to date and that all security patches are applied.